Sceawere
Vulnerability Detail
CVE-2026-70742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:27.007Z",
"pubdate": "2026-08-18T21:17:27.007Z",
"executiveSummary": "An easily exploitable security vulnerability affecting the Oracle Hyperion Financial Reporting product has been identified within the Server component, specifically impacting supported version 11.2.25.0.000.\nThe vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the targeted system, potentially resulting in a complete takeover of Oracle Hyperion Financial Reporting.\nAccording to the CVSS 3.1 scoring system, the vulnerability carries a base score of 8.8, indicating severe risks across Confidentiality, Integrity, and Availability impacts with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.\nThe exploitation requirements demand low privileges and network connectivity, making internal reconnaissance or compromised low-level credentials viable vectors for threat actors.\nSuccessful exploitation leads to absolute control over the affected application, posing significant risk implications for organizational financial data integrity and system confidentiality.",
"technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000, exposing the application to remote exploitation over the network.\nAttackers leverage the HTTPS protocol to interact with the vulnerable service, circumventing certain security boundaries due to insufficient input validation, authorization checks, or flawed session management mechanisms present in the affected component.\nThe attack flow begins when an authenticated, low-privileged threat actor crafts and transmits malicious payloads targeting the vulnerable Server component.\nBecause the attack complexity is classified as low and requires no user interaction, the payload is processed directly by the server, exploiting underlying logic flaws or memory corruption weaknesses.\nUpon successful execution of the payload, the attacker can elevate privileges or execute arbitrary administrative functions within the context of the Oracle Hyperion Financial Reporting application.\nThe post-exploitation impact includes complete system takeover, granting the adversary unrestricted access to sensitive financial datasets, administrative controls, and underlying system resources.\nThe Confidentiality impact is total, allowing unauthorized data exfiltration; the Integrity impact is total, permitting malicious modification of financial reports and system configurations; and the Availability impact is total, enabling denial-of-service or operational disruption."
}